BULLETIN №082Last updated · 29 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 11 Oct 2017 | SANTANDER CONSUMER EFC, S.A.SANTANDER CONSUMER EFC, S.A. was fined by the AEPD for sending promotional SMS messages without the recipient’s consent. The authority also noted that the messages were sent despite the recipient’s objection to receiving advertising. | ES | AEPD | ePrivacy | €8,000 | ↗ |
| 17 May 2023 | Santander Consumer Bank S.p.A.Santander Consumer Bank S.p.A. was fined by the Garante EUR 10,000 for failing to provide timely and adequate access to personal data. The authority also found that prejudicial information related to a loan was not deleted, constituting a breach of GDPR Article 15. | IT | Garante | GDPR | €10,000 | ↗ |
| 01 Jan 2024 | Santander BankIn 2024, Santander Bank was fined 1,440,000 PLN by UODO. The sanction concerned the failure to report a personal data breach, which is a significant breach of GDPR obligations. | PL | Urząd Ochrony Danych Osobowych | GDPR | €331,000 | ↗ |
| 02 Mar 2011 | Santa Caterina Impianti S.p.A.Santa Caterina Impianti S.p.A. was fined 12,000 EUR by the Garante. The authority found a breach for failing to provide the required data protection information under the Italian Data Protection Code. | IT | Garante | GDPR | €12,000 | ↗ |
| 02 Oct 2014 | San Petronio s.r.l.San Petronio s.r.l. was fined by the Garante for failing to appoint data processing officers and for providing inadequate information about video surveillance. The authority found that these practices breached data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 24 Oct 2013 | SANITAS S.A.SANITAS S.A. was fined by the AEPD in the amount of 1,200 EUR for sending unsolicited commercial emails. The authority found that the required information clause was missing, which constitutes a breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €1,200 | ↗ |
| 03 Mar 2020 | SANGIL Y GARCÍA, S.L.SANGIL Y GARCÍA, S.L. was fined by the AEPD 1,800 EUR for sending promotional emails using personal data obtained from the Boletín Oficial de la Propiedad Industrial. The company had no prior client relationship with the recipients, which breached data protection rules. | ES | AEPD | ePrivacy | €1,800 | ↗ |
| 22 Aug 2024 | Sancțiuni pentru încălcarea RGPDThe ANSPDCP fined the company EUR 3,000 for violating Article 2 of the GDPR. The case concerned non-compliance with data protection requirements. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 16 Mar 2023 | Sancțiuni pentru încălcarea RGPDA healthcare operator was fined for unauthorized disclosure and access to personal data. The case concerned data confidentiality and breaches of GDPR obligations. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 16 Mar 2023 | Sancțiuni pentru încălcarea RGPDA healthcare operator was fined for failing to implement adequate security measures, which led to unauthorized access to personal data. The case indicates a breach of data protection obligations under the GDPR. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 25 Jun 2015 | San Bartolo s.r.l.San Bartolo s.r.l. was fined by the Garante for processing employees’ biometric data without prior notification and without the required preliminary verification. The case concerns a breach of privacy rules governing special-category data. | IT | Garante | GDPR | €24,000 | ↗ |
| 08 Sept 2020 | Sanatatea Press Group S.R.L.Sanatatea Press Group S.R.L. was fined EUR 2,000 by ANSPDCP for a data security breach during an online event. Login details were mistakenly sent to incorrect email addresses, resulting in disclosure of information to unauthorized recipients. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 10 Sept 2014 | SAMPLE GESTION S.L.U.SAMPLE GESTION S.L.U. was fined by the AEPD in the amount of 1,100 EUR for sending unsolicited commercial SMS messages despite the recipient's request to opt out. This constituted a breach of Article 21.1 of the LSSI on unsolicited marketing communications. | ES | AEPD | ePrivacy | €1,100 | ↗ |
| 13 Jun 2024 | Samodzielny Publiczny Zespół Opieki Zdrowotnej z siedzibą w P., za naruszenie art. 5 ust. 1 lit. f) i ust. 2, art. 25 ust. 1, art. 32 ust. 1 i 2 oraz art. 34 ust. 1 rozporządzenia 2016/679The Polish DPA (UODO) imposed an administrative fine of PLN 40,000 on the Samodzielny Publiczny Zespół Opieki Zdrowotnej based in P. The decision concerns breaches of Article 5(1)(f) and (2), Article 25(1), Article 32(1) and (2), and Article 34(1) of Regulation (EU) 2016/679. | PL | UODO | GDPR | €9,201 | ↗ |
| 17 Dec 2024 | Sambla Group OySambla Group Oy was fined EUR 950,000 by TSV for failing to adequately protect loan applicants' data. The data was accessible to third parties through unique URLs, which breached GDPR requirements on data protection and security. | FI | TSV | GDPR | €950,000 | ↗ |
| 01 Jan 2025 | Sambla GroupThe Finnish Data Protection Authority fined Sambla Group EUR 950,000 after unauthorized parties accessed credit application data by manipulating web addresses. The authority found that the company had not implemented adequate safeguards to prevent the breach. | FI | Tietosuojavaltuutetun toimisto | GDPR | €950,000 | ↗ |
| 14 Dec 2017 | Salvatore AloiSalvatore Aloi was fined EUR 120,000 by the Italian Garante. The case concerned the processing of personal data of 12 individuals without consent, by activating phone cards in their names without authorization. | IT | Garante | GDPR | €120,000 | ↗ |
| 23 Jun 2020 | SALBEGAP, S.L.SALBEGAP, S.L. was fined by the AEPD EUR 2,000 for installing surveillance cameras in common areas without authorization from the homeowners' association. The authority found that this breached data protection principles. | ES | AEPD | GDPR | €2,000 | ↗ |
| 11 Mar 2020 | SALAD MARKET S.L.SALAD MARKET S.L. was fined by the AEPD €3,000 for using video cameras to monitor employees without informing them. The company also added employees to WhatsApp groups without consent, which breached data protection rules. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 04 Oct 2021 | SAKBO SPAIN, S.L.SAKBO SPAIN, S.L. was fined by the AEPD in the amount of 5,000 EUR for sending unsolicited commercial emails without recipient consent. The conduct breached Article 21 of the LSSI governing electronic marketing communications. | ES | AEPD | ePrivacy | €5,000 | ↗ |